A bold but simple login system
11–20 of 101 posts
Re: A bold but simple login system
#12Thinking of it for enterprise users it could really work. Enterprise users seem to be on Outlook all the time checking their e-mails so this would work if you can't tie your passwords into AD/Exchange. Maybe have an option to have a token that can be entered or a link clicked. I get all my e-mails on my phone so if I received a code that I can enter in my phone that can work. I could also click a link in Outlook and…
Re: A bold but simple login system
#13I do agree with his point that memorizing passwords can get cumbersome, especially with different sets of rules for different logins. However, the majority of people store their passwords in their everyday browser or just stay logged in indefinitely.
The real solution to "doing away with passwords" lies in recognition technology on devices. What if my keyboard could recognize my identity and pass that along to authorized sites as login credentials? What if my iPhone could do the same? I'll defer the argument of privacy in visiting sites where you don't want your identity revealed for another time.
Re: A bold but simple login system
#14Thinking of it for enterprise users it could really work. Enterprise users seem to be on Outlook all the time checking their e-mails so this would work if you can't tie your passwords into AD/Exchange. Maybe have an option to have a token that can be entered or a link clicked. I get all my e-mails on my phone so if I received a code that I can enter in my phone that can work. I could also click a link in Outlook and…
At work we have a policy that smart phones are locked by a PIN. No PIN, no email.
This is not ideal: no mechanism to enforce 'good' PINs, force a user to change them on a regular basis.
Re: A bold but simple login system
#15Present the end-user with a certificate management dialog when they open a browser for the first time. That would allow them to either browse for an existing certificate or create a new one. After one is created they're given a copy which could be used in any other browser at a later time. From that point on, each time a Web server requires authentication it could be handled behind the scenes. No log on page, no passwords, no user names; only aliases and a push button start. Signing up would become a one click affair, as well. Press the button, and the browser sends the public key to the Web server. A site gets hacked? Big deal, there are no vulnerable hashes -- only public keys. You would never be required to remember anything more than backing up your certificate. Worried about recovery? Do what you would do with SSH. Pop the cert on a thumb drive and hide it. Hell, even create a feature in that management dialog to do it for you.
This of course would require a large standards body and the involvement of every major browser company. But in the end, it would be easier.
Re: A bold but simple login system
#16Re: A bold but simple login system
#17Re: A bold but simple login system
#18Re: A bold but simple login system
#19This is how Staticloud[1] works. You put in your email address and receive a log in link. You never have to register; registration and login are the same process. [1] http://staticloud.com/
Re: A bold but simple login system
#20Please, somebody figure out how to get us over the hump to the bright future day when we all have asymmetric keys embedded in hardware and we can leave passwords behind.
or
Please, somebody figure out that when you embed asymmetric keys in people's bodies, we'll end up with a lot of geeks with their hands hacked off with machetes.